(Bob -- feel free to forward this to whatever list(s) you think might be interested -- Nick). I describe an architecture providing usage control (as opposed to access control) for mutually suspicious objects (i.e., objects interacting across trust boundaries), using bearer certificates: http://szabo.best.vwh.net/scarce.html Nick Szabo http://szabo.best.vwh.net/